CVE-2021-40684
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- talend/esb runtime
- Source
- cve@mitre.org
References
- https://help.talend.com/r/en-US/7.3/release-notes-esb-productsRelease Notes, Vendor Advisory
- https://jira.talendforge.org/browse/SF-141Patch, Vendor Advisory
- https://help.talend.com/r/en-US/7.3/release-notes-esb-productsRelease Notes, Vendor Advisory
- https://jira.talendforge.org/browse/SF-141Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.